Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy general
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 17th, 2002, 02:39 PM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Xupiter...anybody know how to

get rid of them? A friend just called me and said this site seems to have taken over his computer. He doesn't know how, but now that they're there, they won't leave.

I don't know any more than that at this point, other than that they've inserted themselves into his registry, taken control of his home page, and won't let go.

I'm firewalled, using Proxomitron with most filters enabled, but still don't feel comfortable trying to investigate the site to see who or what they are.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #2  
Old September 17th, 2002, 02:52 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,718
Default Re:Xupiter...anybody know how to

Here´s lots of info: http://and.doxdesk.com/parasite/Xupiter.html

Wish him luck for me,

Pieter
__________________
Regards,

Pieter
It´s nice to be important, but it´s more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #3  
Old September 17th, 2002, 02:58 PM
MyNethingyman
 
Posts: n/a
Default Re:Xupiter...anybody know how to

You will find at this link a post by Name Game that will give you a direct download link to the Xupiter site and a page that will give you the uninstaller and the proceedure to do it. You must follow the instructions.. If you do the plugin will go away.

http://www.dslreports.com/forum/rema...ty,1~mode=flat

This is a link to the FAQ for Xuipter.
http://www.xupiter.com/help.html



I will post it here also the Uninstaller.

NOTE THIS IS A DIRECT DOWNLOAD LINK.

http://www.xupiter.com/uninstall/

Also note that after you run the uninstaller (make sure no other programs are running) you must immediately Reboot your machine for it to take affect.

Good luck it seems to work for everyone to date.

  #4  
Old September 17th, 2002, 03:07 PM
MyNethingyman
 
Posts: n/a
Default Re:Xupiter...anybody know how to

I will also tell you that none of the Spyware Groups I know of are going after Xupiter today. Xupiter has been pretty upfront on how the do business on the Net..They have unstallers of their products and a good FAQ section.

I guess until that changes..you just have to put up with them.
  #5  
Old September 17th, 2002, 03:12 PM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Re:Xupiter...anybody know how to

Boy, that was quick response. I'll note those URL's and pass them on. I can't believe nobody is doing anything about this outfit. Whether they post uninstallers or not, it's an intrusion.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #6  
Old September 17th, 2002, 03:19 PM
MyNethingyman
 
Posts: n/a
Default Re:Xupiter...anybody know how to

Please do get the word out..now a favor..can you find out where he/she did get it..I am keeping track of that.

If we find out it is in an unsavory way..by websites that are their partners..then that should be noted. But it can not be just and IE setting thing were one could have prevented it with better security setting instead of having it wide open..so far have found that most just download it to see what it was...thanks Chuck,

Regards,

John
  #7  
Old September 17th, 2002, 03:37 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:Xupiter...anybody know how to

Kuddos, John!

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #8  
Old September 17th, 2002, 04:05 PM
MyNethingyman
 
Posts: n/a
Default Re:Xupiter...anybody know how to

Just trying to pay back the great Moderators, you have in here, in a small way for all the help they have given to others. They are very resourceful..and this is fun.
  #9  
Old September 17th, 2002, 04:09 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,718
Default Re:Xupiter...anybody know how to

Quote:
quoting: MyNethingyman link=board=22;threadid=3713;start=0#24903 date=1032293136]
Just trying to pay back the great Moderators, you have in here, in a small way for all the help they have given to others. They are very resourceful..and this is fun.

Well, keep it up. I think you´re good at it

Regards,

Pieter
__________________
Regards,

Pieter
It´s nice to be important, but it´s more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #10  
Old September 17th, 2002, 04:51 PM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Re:Xupiter...John, the guy is pretty sure

it was an About.com pop up that got him. I've given him the URL's and expect he's in the process of ridding himself of Xupiter. I also told him to download Proxomitron or a similar pop up killer.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #11  
Old September 17th, 2002, 04:54 PM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default oops, forgot to add....

that he doesn't remember what website he was on when he got hit, which is probably the most important thing.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #12  
Old September 22nd, 2002, 12:45 AM
Mike_Healan's Avatar
Mike_Healan Mike_Healan is offline
Spyware Expert
 
Join Date: Mar 2002
Location: USA
Posts: 302
Default Re:Xupiter...anybody know how to

This is from my latest newsletter, which won't load right now, because someone tripped over a golf ball or something and knocked the waxed string out of the back of my site's web server. ;(

Anyway....

==================================================
A new "drive-by downloader" has come onto the scene recently. Xupiter.com's browser toolbar has been finding its way onto the computers of countless people via activex installation, and people all over the net have been running around in circles trying to figure out what to do with it. There is an enormous thread at the message boards about this which nearly broke the record for replies to a single topic, and smashed the record for page views with nearly 7,000 hits.

Spybot S&D will soon be updated to handle this software and the other spyware removal companies have been sent the relevant information. If your company produces spyware/adware/hijacker/<insert term here> removal software and you haven't already been receiving notification of potential new targets from me, please contact me to give me an appropriate contact address.

If you have this thing installed and wish to get rid of it now, the manual instructions are as follows (with apologies to Tony Klein for snitching his instructions):

Open the registry (from the Start menu, click Run and enter regedit) and find the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Delete the 'XupiterStartup' entry in the Right Hand pane.

Also delete the following Registry Keys:

HKEY_CURRENT_USER\Software\Xupiter
HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{A27CFCAE-9351-4D74-BFFC-21EB19693D8C}

Reboot, and delete the entire Program Files\Xupiter directory.

You're also likely to have a Xupiter ActiveX object in your Downloaded Program Files folder. Find that one, rightclick it, and choose properties. It has the following ID: {A27CFCAE-9351-4D74-BFFC-21EB19693D8C}

Now rightclick the file, and choose delete.

Next, delete the Xupiter folder in Program Files.

Finally, go to Internet Options/Programs, and hit "Reset Web Settings".

Many, many, many, many thanks to the dozens of people that contributed information to that thread. Most especially to one of the moderators at the forums, who goes by Mr Bones, who actually installed the software to log its installation process.
__________________
www.spywareinfo.com
  #13  
Old September 22nd, 2002, 07:15 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,949
Default Re:Xupiter...anybody know how to

Additionally, a Xupiter install also adds the following Favorites folders you will want to remove: Business, Computers, Cool Stuff, Entertainment, Gaming, Lifestyle, and Shopping.

BTW, I've heard that a SpyBot S&D update due out later today is to include Xupiter detection, which will be a boon for a lot of people.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #14  
Old September 22nd, 2002, 07:19 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:Xupiter...anybody know how to

Quote:
BTW, I've heard that a SpyBot S&D update due out later today is to include Xupiter detection, which will be a boon for a lot of people.

That's for sure! Let's see what Patrick comes up with .

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #15  
Old September 22nd, 2002, 07:29 AM
Primrose's Avatar
Primrose Primrose is offline
Security Expert
 
Join Date: Sep 2002
Posts: 2,743
Default Re:Xupiter...anybody know how to

"This is from my latest newsletter, which won't load right now, because someone tripped over a golf ball or something and knocked the waxed string out of the back of my site's web server. ;( "
___________
Floss twice...keep the string taunt..use bigger coffee cans to get the word out.... on your back swing..just keep your eye on that golf ball.

Thanks for the update.
  #16  
Old September 22nd, 2002, 07:33 AM
Mike_Healan's Avatar
Mike_Healan Mike_Healan is offline
Spyware Expert
 
Join Date: Mar 2002
Location: USA
Posts: 302
Default Re:Xupiter...anybody know how to

Quote:
quoting: Primrose link=board=22;threadid=3713;start=0#25322 date=1032694181]
"This is from my latest newsletter, which won't load right now, because someone tripped over a golf ball or something and knocked the waxed string out of the back of my site's web server. ;( "
___________
Floss twice...keep the string taunt..use bigger coffee cans to get the word out.... on your back swing..just keep your eye on that golf ball.

Thanks for the update.


ROFL!!
__________________
www.spywareinfo.com
  #17  
Old September 22nd, 2002, 10:55 AM
claire
 
Posts: n/a
Default Re:Xupiter...anybody know how to

Hi,
The Spybot's new update includesXupiter
  #18  
Old September 22nd, 2002, 10:56 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,949
Default Re:Xupiter...anybody know how to

Updates of Sept, 22nd:
updated hijacker: CnsMin
added hijacker: Xupiter
added trojan: MS7531, Element
updated spyware: Aureate, HuntBar
added Dialer: TIBS (PayPerViewDialer)
updated dialer: All-In-One Telcom, TTW, Huysuzseks

__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #19  
Old September 22nd, 2002, 01:16 PM
Primrose's Avatar
Primrose Primrose is offline
Security Expert
 
Join Date: Sep 2002
Posts: 2,743
Default Re:Xupiter...anybody know how to

You also have two other methods you can try.


First:Manually you can rename XTUPDATE.DLL

Second:

BHODemon
What does BHODemon do?
BHODemon scans your Registry for BHOs, and presents any it finds in a list. By highlighting a BHO in this list, and clicking the "Details" button, you can see information about this BHO, and even disable it if you wish. BHOs are disabled by simply renaming the DLL that houses them. By renaming the DLL, instead of deleting it, you have the option of enabling it later if you wish. Why would you want to do that? Because the program that installed the BHO will not run if it can't find the DLL: Go!Zilla, for example, won't run if you remove its BHOs.

http://www.definitivesolutions.com/bhodemon.htm


The second method here I am told will take care of more that Xupiter as they try to get the attention of your browser.

Small 127K program.
  #20  
Old September 22nd, 2002, 01:19 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,949
Default Re:Xupiter...anybody know how to

You'll have trouble renaming Xupdate.dll as it will be in use by Windows.

The short method is going to Start > Run > Msconfig, and unchecking XupiterStartup.

Click OK and close Msconfig.

Disable the BHO or delete its registry key.
Now reboot, and rename or delete the dll.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #21  
Old September 22nd, 2002, 01:30 PM
Primrose's Avatar
Primrose Primrose is offline
Security Expert
 
Join Date: Sep 2002
Posts: 2,743
Default Re:Xupiter...anybody know how to

You'll have trouble renaming Xupdate.dll as it will be in use by Windows.

How about your safe or DOS I never had any problems
____________________________________________


Browser Helper Objects: The Browser the Way You Want It
Click here to download sample - 5267.exe.

Dino Esposito
Microsoft Corporation

January 1999

Summary: Describes how to use BHOs to customize your browser. (16 printed pages) Covers:

Introduction
Program Customization
What Are Browser Helper Objects?
The Lifecycle of Helper Objects
The IObjectWithSite Interface
Writing a Browser Helper Object
Detecting Who's Calling
Getting in Touch with WebBrowser
Getting Events from the Browser
Accessing the Document Object
Managing the Code Window
Registration of Helper Objects
Summary

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnbrowse/html/bho.asp





  #22  
Old September 22nd, 2002, 01:34 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,949
Default Re:Xupiter...anybody know how to

Yes, I know, but why just rename the dll?

Let's get rid of the entire thing. That sounds like a much more sensible option.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #23  
Old September 22nd, 2002, 01:40 PM
Primrose's Avatar
Primrose Primrose is offline
Security Expert
 
Join Date: Sep 2002
Posts: 2,743
Default Re:Xupiter...anybody know how to

Yes, I know,

OK

Now we have upteen methods.

yours is fine also. Glad you posted it.

Not interested in a competion.




  #24  
Old September 22nd, 2002, 01:42 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,949
Default Re:Xupiter...anybody know how to

Neither am I.

I'm sorry to hear you seem to regard it as such.

Cheers,

__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #25  
Old September 25th, 2002, 05:57 PM
microwiz3 microwiz3 is offline
Infrequent Poster
 
Join Date: Sep 2002
Location: Goshen, IN
Posts: 6
Default Re:Xupiter

Hope this might be of some help!
Here is where my wife "acquired" Xupiter recently:

http://wwx.dollhouseminiaturesclub.freeservers.com

Then go to the "Craftroom" and a screen extoling the virtues of Xupiter having a "certificate" should appear.
(The usual ActiveX approval screen).

Interestingly enough although I found it on her computer it had never activated. I just happened to see a directory named Xupiter when I was looking around for something else. Removed without a hitch.

Also Lavasoft (AdAware) has included Xupiter in the files as of 9-24-02. I went in and "acquired" it just to test and AdAware caught it and removed it with no problem.

I don't think we have seen the last of these guys. Hope this helps. Happy computing!

URL provided has been altered for security reasons - Forum Admin
 

Wilders Security Forums > Privacy Related Topics > privacy general « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:10 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums